From nobody Tue Sep 29 08:22:34 2026 Received: from mail-pg1-f182.google.com (mail-pg1-f182.google.com [209.85.215.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 56493412276 for ; Mon, 10 Aug 2026 17:10:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381849; cv=none; b=J3a9uQSAr+jAUrSNzMnG6/FqXv9/c3YjcTbwisoC2xJB/0u9NuCzgEzMCiTu/g18+hmSsIqPBmnVnyB9nPq+WV3eBL7p/v1rAQeIJ5p2HUD1hgxkfNWu9NDUF3vki0TRUIdS5Ab8GkD1Q4jJpesybn+BaxJIEqIsem7zZl4Qcjs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381849; c=relaxed/simple; bh=j+tqaF49vVrcAgCqivH0Q0gH+G4z0Uw2YSxLSLYQ6dc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=qXqsF1lAH5cn0zj80rkCV1B+zuRZcqigqfJ1arDo9HD+2Lule6ZEKnVK/5g3l3sDVbot24cUWir86AwLtQpRqGbDLUS11v3VukQTLlyVpLkbo3YQ5NcTKnKPCLel59WR0+TVOqabCAt5xnwg4jjzIPFTMjjwPrY75NfGqjOUP58= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=C2ektfiN; arc=none smtp.client-ip=209.85.215.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="C2ektfiN" Received: by mail-pg1-f182.google.com with SMTP id 41be03b00d2f7-cb5a6aa8760so1177601a12.1 for ; Mon, 10 Aug 2026 10:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786381847; x=1786986647; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=o17hX9psIIM1rya7TZerzwkpY1R4GKMlzn2vF2QyCKI=; b=C2ektfiN94yCBjhkL/mjM+Dpb9Uqj0uRcDTvOMp1VPZAQp0B06RRE2DXc9hU2wYIOV mgKSpnILRm9v1AZvOtijFG114SUUBGLZgyO9gexQBQuOzR9kf1Fks6wA+RV/UmLsdB6Q jpVI6fmD6QYuILwlFTWhXesySsTMpe706NcAcASlnXz9IQB2WOBQtUrbPmUJLaC3pFPZ nIwTesGiPTaVrt4XTMkRgCxKbp7CNry494xcjPhZVW+74dd7uhER5Vl9BjQJezQf7Tz8 EaDUFnN/JsKQbtv0sPkJ9246hQJDGWXtNr5cvg/zcCbphy6P1jffbF5o6nZ9eMfrBXuT j9nw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786381847; x=1786986647; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=o17hX9psIIM1rya7TZerzwkpY1R4GKMlzn2vF2QyCKI=; b=ZLpfahauDR7Q5Uig+UNfbYsu15G1WwyHB7nEFa4Bp/QB/E3dpTJSCewrocdOxtlOr9 KWHgTi/fS1AxAMHPHrxVtgmXHnetc7DypdiJ65ZMjA7iiW6UQFUFzazS6iBWJZys+Rxv atlCW3dBPIZRypVdq+PNFoz/qN+TWCn96z3freZ4KpzsehfXtnMvzMzL9yPmabSTK1Ve C4MeuWtH+BcBqZOJhUM5DqhfSkg/+CEsN9dr3e9B1/bKwMimwxdCP+G1cuPIlSgu6zBa n/uehmPucBJVF8l1nUbUngKgJLVgM8zVknYtb7VRFJk57GtB128UrL/wF7OgfgASI3vd V3xA== X-Forwarded-Encrypted: i=1; AHgh+Roj0nrfQRCNsMrXhJWxLM5uCKSwm7XE0OiHsrRtTMKxz1nPOSITqHxpv8PvBSf3f3WM2QMB4j7AHiciMdE=@vger.kernel.org X-Gm-Message-State: AOJu0Yyt2X8gNB+3PBH2JHiZH7KQTV5EtIUTEAp2YWYiAfgAIHmQI708 JFD19yIsP5e87Icbdxm5p+P/9+OdBXhEoFQBoKPAsMMZ0WrFlT/iK45z X-Gm-Gg: AR+sD12zFC8xhNDCwL0+3AKW7WHY+MkBVq3ZqDmA3f8IbfcgWtrVUXO2o1wFuh8MzRJ XWdeVAW4yaHSzOYH1jmPjVhJBq+M5MePMotgJBpGYpIxg3RZkBhCM3nkgCYL8ALU7Y23haZcqNd zUi1w4MpKPy1jxwJ/9F/wQUwV6Q6Y6B6189Cn4nbgETTp6yHJFmCysnjrCU6KgLDftdmjpYFGUE 3DmpvBSFnm9GCJ+5is3Tetox0Pmad/R0vB1lqCHo4Xk8QfkHVOi68HcyWriaIMHnJo0KX9XlUff HNlQGrmAVTR75XmzkCwJbTxIZ4bfqB3YYWoVEhGfUYpxosfVmuxhjR04JTf6Ugmba9i1fPvelmt 91OiW37ev39KUOrD0VKgmmRTWxF4R1e0VMOxrTsUe9t9cFfec8yRuJrjGSTu4YxIIIeCSWo+ORe TE74u/SlGFLWzxeEEgPPysp01KELPwb85DsEP+gYPxEheX8tqIko7DGfbJk8CedA== X-Received: by 2002:a05:6a20:db92:b0:3c4:147e:98f1 with SMTP id adf61e73a8af0-3cbadcfd00emr37452298637.31.1786381847406; Mon, 10 Aug 2026 10:10:47 -0700 (PDT) Received: from phi.nguyendp ([116.86.160.247]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-1410199cf49sm37194663c88.3.2026.08.10.10.10.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 10:10:46 -0700 (PDT) From: Nguyen Dinh Phi To: Stefano Garzarella , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , George Zhang , Dmitry Torokhov , Andy King Cc: Nguyen Dinh Phi , syzbot+1b2c9c4a0f8708082678@syzkaller.appspotmail.com, Michal Luczaj , virtualization@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v5 1/3] vsock: don't check the listener's sk_err in vsock_accept() Date: Tue, 11 Aug 2026 01:09:30 +0800 Message-ID: <20260810170935.2242314-2-phind.uet@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260810170935.2242314-1-phind.uet@gmail.com> References: <20260810170935.2242314-1-phind.uet@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Syzbot reported an issue which can be reproduced with these steps: r0 =3D socket(AF_VSOCK, SOCK_STREAM, 0) bind(r0, {VMADDR_CID_ANY, PORT}) connect(r0, {VMADDR_CID_LOCAL, PORT}) -> -1, EPROTO (self-connect) listen(r0, backlog) -> 0 r1 =3D socket(AF_VSOCK, SOCK_STREAM, 0) connect(r1, {VMADDR_CID_LOCAL, PORT}) -> 0 accept(r0) -> -1, EPROTO (stale sk_err) Basically, it creates a socket (r0) and triggers a self-connect after binding it. This self-connect fails with EPROTO because it loops back to r0 while the socket is still in the TCP_SYN_SENT state, causing it to be incorrectly dispatched to the connecting-client path. The unexpected packet type encountered there sets sk_err to EPROTO. After that, it invokes a listen() call on the same socket. This listen() call succeeds because the kernel's listening path never inspects or clears sk_err. Then, a new socket (r1) is created as a normal client and connects to r0. However, vsock_accept() rejects this incoming connection because the listener's sk_err still holds the EPROTO error from the earlier failed self-connect. This rejection causes the child socket created for r1's connection to never be freed on virtio or hyperv transports; only the VMCI transport implements pending_work to revisit and clean up a rejected socket. For a non-blocking connect(), vsock_connect() may return -EINPROGRESS immediately, and vsock_connect_timeout() can later set sk->sk_err asynchronously. Since no vsock transport ever sets sk_err on a socket while it is in TCP_LISTEN state, checking it in vsock_accept() serves no purpose and only carries forward errors left behind by earlier, unrelated connection attempts on the same socket. Remove the checks so accept() no longer rejects valid incoming connections because of a stale error, which also avoids the resource leak described above. Fixes: d021c344051a ("VSOCK: Introduce VM Sockets") Reported-by: syzbot+1b2c9c4a0f8708082678@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D1b2c9c4a0f8708082678 Suggested-by: Michal Luczaj Signed-off-by: Nguyen Dinh Phi --- net/vmw_vsock/af_vsock.c | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index 622dbd046799..ff507761f472 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -1893,7 +1893,7 @@ static int vsock_accept(struct socket *sock, struct s= ocket *newsock, timeout =3D sock_rcvtimeo(listener, arg->flags & O_NONBLOCK); =20 while ((connected =3D vsock_dequeue_accept(listener)) =3D=3D NULL && - listener->sk_err =3D=3D 0 && timeout !=3D 0) { + timeout !=3D 0) { prepare_to_wait(sk_sleep(listener), &wait, TASK_INTERRUPTIBLE); release_sock(listener); timeout =3D schedule_timeout(timeout); @@ -1906,12 +1906,6 @@ static int vsock_accept(struct socket *sock, struct = socket *newsock, } } =20 - if (listener->sk_err) { - err =3D -listener->sk_err; - } else if (!connected) { - err =3D -EAGAIN; - } - if (connected) { sk_acceptq_removed(listener); =20 @@ -1941,6 +1935,8 @@ static int vsock_accept(struct socket *sock, struct s= ocket *newsock, =20 release_sock(connected); sock_put(connected); + } else { + err =3D -EAGAIN; } =20 out: --=20 2.53.0 From nobody Tue Sep 29 08:22:34 2026 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5F92242F702 for ; Mon, 10 Aug 2026 17:10:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381853; cv=none; b=JwCH2T+79UWrkZvxTTRAj4jOxh3VShj62XUgKGEqiZjFJcr+9RukizkYCfznA4suF0+hxg6h31e4E5t9p8aGp9+JqzDvT4QcAzIVOvAnjS+aoHhtGszB2qW2jvIVkZSmkwC/6agh3ntEwRmhZmB+yl163WOVSKf5WzdnS/Jhw5s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381853; c=relaxed/simple; bh=UG8CVmhUiNXkcyAixv/sxJGkEM5W+KEMJZCoNAJk8ho=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=bGrNixc2ZJjYa4aR6R9x2lblNO9sRK6T+XgVtgEBCsQxCerODuFKDhBvri1SCyZxeOE2ouRIyVUW8BA0WxZGdBOm2F+vElLgDc9OxNharpAECRNSKnb+p56JAMBxrDdmOkEku04T7snkxJpEcfD1N5Jg87M4IN/rdWgQNAxssVA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Koh39bO7; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Koh39bO7" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38101f85591so126288a91.1 for ; Mon, 10 Aug 2026 10:10:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786381852; x=1786986652; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HIzXZz56o+MmOQNy7Jnj/dfQQWOM2HS0FnwvviI6E/Y=; b=Koh39bO7kdpGXz6+0PN/XmN9NeQ092SUPi/mRMIWe7nA349shVdRyYlAl2E9xB/c7I U44FKSd1p6YaGAdY2CrCbOAQ93jkYNgjw/wLUYsO4OVJMwcawuVYZz4GEwiCiLkAZFdv S/WfzLHNCqF4rpfeP+WVEsYIdmz9JKRY+OVZcWc2riJwSQpqYf0ouHkkZxpA8crgqpL0 ev3nzSebLLMbyd8AyqI6QHcw5LaYQDFbmwRuP7yDRI4Krxxs38wjGx/uBitThTfHFS5Y 22G/XNDvPyNjiQl5opvWVbRNak1yFj3gpCN0Jtbdsqs1xx6abgT1ENs2rwvav5sPLtqB WnUg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786381852; x=1786986652; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HIzXZz56o+MmOQNy7Jnj/dfQQWOM2HS0FnwvviI6E/Y=; b=WkbfoCtQW8Gs03VxHL1OOXhk85OaFtIAiQZqIsVxBAk+sw1Xk4EvOnEKyRnYRo/QaG qtPxTPrmbGdKka1BW4QvknyjHk5B5e7Z1LuwzgmCocIDDywVUVcGujNeSwa5ogYSvoxB Q9In5jM1unH9DJJxbru2liSOs1Cxtrjlq/nMNOMDjhpHl894abIC+BsqvXBSJ2KqhnKZ wcx38ZyIxTCbyJ7iH6ihTBfbgNmVw+KdUpFNbPoZWE3+HHRs+EXA9OmcZWI0Wq8Xa02u NbEPzXmuAo5MFTEGxX6ITNW5OgUez2DZ3/3ebJjQnUVxBAEB3hx1uBWYf1RQBROyzxFn pc2g== X-Forwarded-Encrypted: i=1; AHgh+RrqzLmWhXaH0yBvFffJYlw8xMzkErWXM+edoU3uEdBr7FRjmKDIGsAiJ9sYkQoXA5A1pyZeap95zjaZKJk=@vger.kernel.org X-Gm-Message-State: AOJu0YxnDw+7zJ0Nm3EX9rP7QRzje4Mne5XMTGK6NYMWmj2hHNhMsEYW 0H/+DywySTNsfHJWUIQgatiy03QVoqOHxs88BmlfoH+DndgwKAILNDHJ3MSviBl7 X-Gm-Gg: AR+sD12Wr9TT2dJGHN4T8fctphHkTXD7Ufo/acOY635iBKMgQR4LHcstpZymCAxBdNr tpAsUcfxtf4SIgUAR+bA6486BtNflpWtx0Dyo9PidRXdfnu3dzgjM+tUT4i3x5z3Aty7P6LaNXP 301LmxM1qf9/nUhjshkdDtg0bSbVWVjhuoYtpkJCLyDF4Al4XN9mOBiwIEQabSP7wIRj+r0FjrK tuG5L6afqpKMorbQne3d3bQgxbF1N+kQT2Ea8sSKV7kYDcUuEPZ4GNvegZffFBg9VQYsfTf85d4 6VdA6mswCZTzOga8Vkkdg3zG5mKvvH1Z+gNCOhezgns0ZMzfMwblhXE9cizQ58ZEeJTP512+Bgv Mj8hTvXyHpsG6nSkMPv8XLTMwz6BKHqqDKSGJ2StJPC9Zen8SKRS6L0d7lDpo34MWcf7IOs77Do YeO7rQObSmuQCZqRl8G1cex1LErX4aTU3OucLLSjwZXqKN+O5ZPmzP8i9YW336NQ== X-Received: by 2002:a17:90b:4c42:b0:38f:cab0:9aa9 with SMTP id 98e67ed59e1d1-39284703808mr10229761a91.13.1786381851592; Mon, 10 Aug 2026 10:10:51 -0700 (PDT) Received: from phi.nguyendp ([116.86.160.247]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-1410199cf49sm37194663c88.3.2026.08.10.10.10.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 10:10:50 -0700 (PDT) From: Nguyen Dinh Phi To: Stefano Garzarella , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman Cc: Nguyen Dinh Phi , virtualization@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v5 2/3] vsock: remove the now-unused rejected flag Date: Tue, 11 Aug 2026 01:09:31 +0800 Message-ID: <20260810170935.2242314-3-phind.uet@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260810170935.2242314-1-phind.uet@gmail.com> References: <20260810170935.2242314-1-phind.uet@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" After previous patch, the branch marking a socket rejected in vsock_accept() is unreachable, and nothing ever sets vsk->rejected elsewhere. Therefore, we can remove the `rejected` field from vsock_sock structure. Suggested-by: Stefano Garzarella Signed-off-by: Nguyen Dinh Phi --- include/net/af_vsock.h | 5 +---- net/vmw_vsock/af_vsock.c | 46 +++++++++++++--------------------------- 2 files changed, 16 insertions(+), 35 deletions(-) diff --git a/include/net/af_vsock.h b/include/net/af_vsock.h index 30046a3c20f7..3357ee62d10b 100644 --- a/include/net/af_vsock.h +++ b/include/net/af_vsock.h @@ -52,13 +52,10 @@ struct vsock_sock { * The listening socket is the head for both lists. Sockets created * for connection requests are placed in the pending list until they * are connected, at which point they are put in the accept queue list - * so they can be accepted in accept(). If accept() cannot accept the - * connection, it is marked as rejected so the cleanup function knows - * to clean up the socket. + * so they can be accepted in accept(). */ struct list_head pending_links; struct list_head accept_queue; - bool rejected; struct delayed_work connect_work; struct delayed_work pending_work; struct delayed_work close_work; diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index ff507761f472..b59890bbd217 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -38,10 +38,9 @@ * pending socket. When that socket reaches the connected state, it is re= moved * from the listener socket's pending list and enqueued in the listener * socket's accept queue. Callers of accept(2) will accept connected sock= ets - * from the listener socket's accept queue. If the socket cannot be accep= ted - * for some reason then it is marked rejected. Once the connection is - * accepted, it is owned by the user process and the responsibility for cl= eanup - * falls with that user process. + * from the listener socket's accept queue. Once the connection is accepte= d, + * it is owned by the user process and the responsibility for cleanup falls + * with that user process. * * - It is possible that these pending sockets will never reach the connec= ted * state; in fact, we may never receive another packet after the connection @@ -49,9 +48,7 @@ * future, after some amount of time passes where a connection should have= been * established. This function ensures that the socket is off all lists so= it * cannot be retrieved, then drops all references to the socket so it is c= leaned - * up (sock_put() -> sk_free() -> our sk_destruct implementation). Note t= his - * function will also cleanup rejected sockets, those that reach the conne= cted - * state but leave it before they have been accepted. + * up (sock_put() -> sk_free() -> our sk_destruct implementation). * * - Lock ordering for pending or accept queue sockets is: * @@ -774,11 +771,10 @@ static void vsock_pending_work(struct work_struct *wo= rk) =20 if (vsock_is_pending(sk)) { vsock_remove_pending(listener, sk); - } else if (!vsk->rejected) { - /* We are not on the pending list and accept() did not reject - * us, so we must have been accepted by our user process. We - * just need to drop our references to the sockets and be on - * our way. + } else { + /* We are not on the pending list so we must have been accepted + * by our user process. We just need to drop our references to + * the sockets and be on our way. */ cleanup =3D false; goto out; @@ -942,7 +938,6 @@ static struct sock *__vsock_create(struct net *net, vsk->listener =3D NULL; INIT_LIST_HEAD(&vsk->pending_links); INIT_LIST_HEAD(&vsk->accept_queue); - vsk->rejected =3D false; vsk->sent_request =3D false; vsk->ignore_connecting_rst =3D false; WRITE_ONCE(vsk->peer_shutdown, 0); @@ -1912,26 +1907,15 @@ static int vsock_accept(struct socket *sock, struct= socket *newsock, lock_sock_nested(connected, SINGLE_DEPTH_NESTING); vconnected =3D vsock_sk(connected); =20 - /* If the listener socket has received an error, then we should - * reject this socket and return. Note that we simply mark the - * socket rejected, drop our reference, and let the cleanup - * function handle the cleanup; the fact that we found it in - * the listener's accept queue guarantees that the cleanup - * function hasn't run yet. - */ - if (err) { - vconnected->rejected =3D true; - } else { - newsock->state =3D SS_CONNECTED; - sock_graft(connected, newsock); + newsock->state =3D SS_CONNECTED; + sock_graft(connected, newsock); =20 - set_bit(SOCK_CUSTOM_SOCKOPT, - &connected->sk_socket->flags); + set_bit(SOCK_CUSTOM_SOCKOPT, + &connected->sk_socket->flags); =20 - if (vsock_msgzerocopy_allow(vconnected->transport)) - set_bit(SOCK_SUPPORT_ZC, - &connected->sk_socket->flags); - } + if (vsock_msgzerocopy_allow(vconnected->transport)) + set_bit(SOCK_SUPPORT_ZC, + &connected->sk_socket->flags); =20 release_sock(connected); sock_put(connected); --=20 2.53.0 From nobody Tue Sep 29 08:22:34 2026 Received: from mail-pg1-f177.google.com (mail-pg1-f177.google.com [209.85.215.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D87D842F6ED for ; Mon, 10 Aug 2026 17:10:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.177 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381858; cv=none; b=BbV7abbbD6cC/lf8P7X7c9HgfRUcZsQKX7AgiHXbIGvTB2kCd6eT8gTyWw49tgyrHuZOfdXMFDWHdkeHUu+OfjBz+JUNwn3U0B+UPhxAy6E0mjsqWBAzWxrz52Zhbh+nKQU7sBq4MUekchW19ZSd83jTb8AlhA9LzyfBvhPyW6g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786381858; c=relaxed/simple; bh=P9yChhC5nEAPRJBgrn49F1A2elik1HxqQF0r8qN6qek=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=IWr2lxBnuyDS9vz7AsWbQmMGq8/0gzbM/JJsncWTvUECIFqhFA+8HEVtrcTf3gJsHAtSkGbWTdE14LTnvsxTdTUt0/Yyre7IykhxCkvIHrz7rRVdHKaCNFVs8yenFKHVNElphGSviFgV2pRYUSRtYgiQ+KYVN0wVgRPKvZjlr2E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=Avd80ZSk; arc=none smtp.client-ip=209.85.215.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="Avd80ZSk" Received: by mail-pg1-f177.google.com with SMTP id 41be03b00d2f7-c9e607d81fcso1249169a12.2 for ; Mon, 10 Aug 2026 10:10:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786381856; x=1786986656; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JhsqyhzE48bljLLTr+dFhyiqwriY9sOBMtlHTtICd3s=; b=Avd80ZSkOicBcGVtsD7BWjbpvUVp7NwN6QlSYiW6CREUAFYkKlqLm5aiiYUI7208fs Bf22+zgU+p/3MuzcRv8pHoTwF66dX1vaZPzP3EYe2fzRCB2CbLMW/jatm7LTgpPF6c1n B5TxyLckYSvXZZIGd3wOgsQRSXYbJ0xX+CWOFq0y0pgPzdWYDeV+DuFLqsbK/Oi8DwNN 0gkUKU0s0+0aOKRKe9XIpf71w3Qoq4E1HFzGQYQ5yXTqKpDVsuWMQDdOX89glmxKzLx7 zamE3SNtI0ITKIoNAEpG7jhUUq4yF5wgFi0uUgkaE7QDYbtd7+qgUgUzl0XN12g+0YaS ciQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786381856; x=1786986656; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JhsqyhzE48bljLLTr+dFhyiqwriY9sOBMtlHTtICd3s=; b=J5Tng2hD1UPk2i94gSeKMZfWjUWMJ1x7OdIPo/ArzUzwmf6dmkHQkp09DrT9awkh/A 2VywUxQbXXSF/LzcnGYK3GiW7r7j/SdP3m/bnsVTHSQQB1m5rtCxwomxjcVZqr8QFU9K 43vx49vm0/IuTASFJcbSGXeJYc1zCg93wq4TDqstuIXCU9MJrEZdKwQhsJya7CFplk+z rhhAcBrMGbDnjMjFBZhP3GlAeqnjTLpua4saQvp+aIB3kd7ox+ES2s/1AsGaT3T5zeb/ PE+44grq0WtvC+AmjyjtDs+sCLK/cmKMRymPmUsQal1TU0IM/nSho+WKg8xHJlnQmTcb hT7w== X-Forwarded-Encrypted: i=1; AHgh+RpngOX5vpO9bfp0gOHMRyKZUhbblRS6DpdAGWYpl/YlYejx+z0NlgC8NLP7O2kf6TCJJP52r1goPjlzIyM=@vger.kernel.org X-Gm-Message-State: AOJu0YzWu47/gSNYKXgMiqREcNyz3tmXqiwUsaGZ8JYDki91qVSHxGnc cf3GA8Eb/6WvLK3Uf8ohfirQFJvs0fb31+57ZUFdgEeFnDQBgJaP/kfv X-Gm-Gg: AR+sD11F9zshiZ1BgyzMOF6tQi2JmXDc6CTVWnJNtSPoVpMMIfzhr0bRygK3sXb1LrE xj2kUpHBWIEpZBhF632i0a6MoJsp1Xex4E63rRtapZrEDIwxY6oG+gcR83ayMVCqiEGWEw7Uxv3 gw2LSJJNn5zI6mRdusucUW7nAqNvFSPP17kflk57H3rOv/9cUfKBfqE5dp9IADSyci2FAAy/XzA MT1qCVq1KyHi7ZAGoRz+TsaQFiZhKWdT+da0a5TzhwMP1/UrRzxh3wbowAIln/iTNS2IuglUKEf Cr5DdA1ZARS7LVixBDVUHi0b71yzcPR53IU0GqTcqfzcVf1LytNyVGmd7OfS83UWohNkXJE3woY hQIoHqkGqDFVaxR4Tla2vCehmE0hZjIRZke+ITRQxbzguZm7vHmtrnPZBgoyzH1Mbw5Hd8qVlns gKIDEEssiKWmVX9tckAHTVF0Y0riooQZANjcXkuRrEQjIz4QXlo4AaNX/CsVDBlg== X-Received: by 2002:a05:6a20:7344:b0:3b4:5ff3:45cb with SMTP id adf61e73a8af0-3cbada660a2mr33795635637.8.1786381856114; Mon, 10 Aug 2026 10:10:56 -0700 (PDT) Received: from phi.nguyendp ([116.86.160.247]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-1410199cf49sm37194663c88.3.2026.08.10.10.10.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Aug 2026 10:10:55 -0700 (PDT) From: Nguyen Dinh Phi To: Stefano Garzarella , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Dmitry Torokhov , Andy King , George Zhang Cc: Nguyen Dinh Phi , Wupeng Ma , virtualization@lists.linux.dev, netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH v5 3/3] vsock: use sock_error() to consume sk_err after a failed connect Date: Tue, 11 Aug 2026 01:09:32 +0800 Message-ID: <20260810170935.2242314-4-phind.uet@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260810170935.2242314-1-phind.uet@gmail.com> References: <20260810170935.2242314-1-phind.uet@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" vsock_connect() returns sk_err to userspace but does not clear it: if (sk->sk_err) { err =3D -sk->sk_err; For a blocking connect() the error has already been delivered as connect()'s return value, so leaving it set causes subsequent operations like poll()/epoll() to keep reporting POLLERR even though the connect failure was already delivered. The error should be consumed once it has been returned to userspace. Switch to sock_error(), which reads and clears sk_err atomically, matching the behavior of other protocol implementations such as __inet_stream_connect(). Fixes: d021c344051a ("VSOCK: Introduce VM Sockets") Tested-by: Wupeng Ma Signed-off-by: Nguyen Dinh Phi Reviewed-by: Stefano Garzarella --- net/vmw_vsock/af_vsock.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/net/vmw_vsock/af_vsock.c b/net/vmw_vsock/af_vsock.c index b59890bbd217..1a287719f24a 100644 --- a/net/vmw_vsock/af_vsock.c +++ b/net/vmw_vsock/af_vsock.c @@ -1842,12 +1842,10 @@ static int vsock_connect(struct socket *sock, struc= t sockaddr_unsized *addr, prepare_to_wait(sk_sleep(sk), &wait, TASK_INTERRUPTIBLE); } =20 - if (sk->sk_err) { - err =3D -sk->sk_err; + err =3D sock_error(sk); + if (err) { sk->sk_state =3D TCP_CLOSE; sock->state =3D SS_UNCONNECTED; - } else { - err =3D 0; } =20 out_wait: --=20 2.53.0